Sceawere
Vulnerability Detail
CVE-2026-96416UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IEEE 802.11 Dissector DoS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 15h ago
- Vendor
- Wireshark Foundation
- Product
- Wireshark
- Attack Type
- CWE-122: Heap-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-29T10:17:16.200Z",
"pubdate": "2026-09-29T10:17:16.200Z",
"executiveSummary": "A vulnerability has been identified within the IEEE 802.11 protocol dissector affecting versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18. This flaw allows a remote attacker to trigger a denial of service (DoS) condition by inducing a crash in the protocol parsing logic.\nThe vulnerability type is categorized as an improper input validation or memory handling error during the dissection of IEEE 802.11 frames. Impact involves the unexpected termination of the application or service utilizing the dissector, leading to a complete loss of service availability for the affected component.\nThe risk implication is significant for systems that rely on real-time packet inspection and network analysis, as an attacker can remotely crash the service without prior authentication. Exploitation requires the attacker to be capable of injecting or sending specially crafted IEEE 802.11 frames that the target dissector will process. Once the malicious payload is ingested, the parsing logic fails, resulting in an immediate crash of the execution environment.",
"technicalDetails": "The root cause of this vulnerability lies in the improper processing of malformed IEEE 802.11 frames within the protocol dissector. When the dissector encounters a frame containing specific, unexpected, or malformed data structures, the parsing logic fails to handle the exception or boundary condition correctly, leading to a fatal error.\nThe exploitation method involves the transmission of a crafted IEEE 802.11 frame designed to trigger an out-of-bounds read, null pointer dereference, or buffer overflow within the dissector's state machine. Because the IEEE 802.11 dissector is responsible for decomposing complex encapsulated headers and payloads, it often operates on unvalidated network input at a low level of the OSI model.\nThe attack flow begins with the attacker constructing a malicious packet that adheres partially to the IEEE 802.11 protocol specification but includes anomalous field values, truncated lengths, or invalid type-subtype combinations. Upon receiving these frames, the vulnerable dissector attempts to map the headers into internal structures. During this phase, the logic fails to perform sufficient sanity checks on the length or type fields. This failure causes the dissector to access restricted memory regions or attempt operations on null pointers, resulting in a crash.\nThe vulnerable component is the IEEE 802.11 protocol dissector within the affected software product. The flaw is present in versions 4.6.0-4.6.8 and 4.4.0-4.4.18. Since this dissector is often integrated into network traffic analysis tools, security monitoring appliances, or wireless drivers, the vulnerability is exposed to any network environment where malicious 802.11 traffic can reach the target interface. No authentication or elevated privileges are required for an attacker to initiate the crash, as the dissector processes incoming frames by design.\nPost-exploitation, the service running the dissector stops responding, preventing further packet inspection or network analysis. In production environments, this can lead to a failure in security monitoring infrastructure or network management, potentially masking subsequent malicious activities or causing operational downtime. The recovery typically requires a manual restart of the service or process after the malformed packet flow is ceased."
}